App Security Architect.

Posted 2 Days Ago
Be an Early Applicant
Detroit, MI, USA
In-Office
Junior
Professional Services • Consulting • Industrial
The Role
Design, assess, and support secure application architectures. Perform threat analyses, validate penetration test and code-scan results, identify vulnerabilities, quantify and communicate risks, recommend mitigations, ensure compliance (HIPAA, SOX, CMS), and collaborate with development and business teams throughout SDLC. Provide security guidance across web and database tiers and promote security awareness.
Summary Generated by Built In
Company Description

 

 

Job Description

App Security Architect.

Length of Contract: 24+ months.  Long-term assignment.

Location: Detroit, MI

Description:

The Application Security Architect will report to the Application Security Architect Lead and will be responsible for assuring that IT application software and infrastructure is designed, implemented, and operated in accordance with applicable security standards and practices.  Primary responsibilities include applications security, risk assessment, validation of security pen test results, problem resolution, system documentation, and system security management and support.

Position Responsibilities:

•             Serve as primary information security interface to the assigned projects to collaborate with business representatives, systems development and business users for establishing business requirements, information security functional requirements, security solution options and implementation plans

•             Good understanding of the architecture and the various web application tier and database tier components: underlying objects, schemas/products, database objects, file system structure, tables, views, packages, procedures, sequences, indexes, and constraints

•             Conduct information security threat analyses on new and changed application development initiatives towards design, review, and incident response planning.

•             Identify security requirements for applications, services and supporting infrastructure and effectively communicate requirements to application development teams and business owners

•             Review application source code for vulnerabilities, using both manual and automated code scanning techniques aka Whitebox Testing.

•             Identify and explain the risks associated with common application vulnerabilities, demonstrate exploitation, and recommend mitigation options.

•             Determine and clearly communicate quantitatively where possible  the information security risks to the application development teams.

•             Identify threats and risks to the confidentiality, integrity and availability of all data residing on information systems platforms.

•             Recommend appropriate security solutions and review remediation activities for completeness.

•             Assure compliance to security policies, standards, and procedures, including HIPPA, SOX, and CMS compliance.

•             Monitor and recommend changes in standards that affect application security, especially in the area of privacy and identity theft.

•             Initiate and promote activities to foster information security awareness and education among application development.

•             Work with Information security peers and manager to assure standards compliance on various platforms (e.g., OSs, databases, networks, etc.) upon which application development group relies for the operation of its applications.

•             Knowledge of operating systems (Windows, Unix) and common COTS products used to deliver web services, including IIS, Apache, Tomcat, Oracle Application Server, WebSphere, etc.

Top 3 Skills/Experience:

1.            Skilled to identify and explain the risks associated with common application vulnerabilities, demonstrate exploitation, and recommend mitigation options.

2.            Ability to be the primary information security interface to the assigned projects, and collaborate with business representatives, systems development and business users for establishing business requirements, information security functional requirements, security solution options and implementation plans

3.            Skilled to determine and clearly communicate quantitatively where possible  the information security risks to the application development teams.

Required Skills/Experience:

o             Advanced written and verbal communications skills

o             Experience with a variety of information security processes and technologies such as:

•             Common operating systems, network protocols, web services and databases

•             Risk assessment and management

•             Identity management and authentication

•             Directory services

•             Application security and systems development life cycle

•             Data and systems integrity controls

•             Encryption technology

•             Business requirements development and technical architecture development

•             Change control and release management

•             Network and application security assessment and ethical hacking

•             System planning and integration

o             Ability to adjust to changing priorities while multitasking effectively

o             Ability to design, evaluate and document processes and lead teams in accomplishing process review and improvement

o             Ability to interact with technical managers and development teams to articulate requirements and processes while collaborating on design options, implementation, testing and user acceptance

o             Experience in project management, change management and release management

o             Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content

o             Knowledge of database applications, spreadsheet design, and report writing software

o             Minimum 2 years experience in a security or related IT function

Preferred Skills/Experience:

•             CISSP, CCNA, CCENT, CCNP, GSEC, MCSA, CISM certifications are preferred

Educational Requirements:

•             Bachelors degree in Computer Science, Information Systems, Engineering or related major

Skills Required

  • Minimum 2 years experience in a security or related IT function
  • Advanced written and verbal communications skills
  • Experience with common operating systems (Windows, Unix)
  • Experience with web servers and app servers (IIS, Apache, Tomcat, Oracle Application Server, WebSphere)
  • Experience with web services and databases (application tier and database tier knowledge)
  • Risk assessment and management
  • Identity management and authentication experience
  • Directory services knowledge
  • Application security and systems development life cycle (SDLC) experience
  • Static and manual source code review (whitebox testing) and code scanning
  • Network and application security assessment and ethical hacking/penetration testing validation
  • Knowledge of encryption technology and data/system integrity controls
  • Business requirements development and technical architecture development
  • Change control and release management, system planning and integration
  • Ability to design, evaluate and document processes and lead process improvements
  • Ability to interact with technical managers and development teams to articulate requirements and collaborate on design, implementation, testing and UAT
  • Experience in project management, change management and release management
  • Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content
  • Knowledge of database applications, spreadsheet design, and report writing software
  • Bachelors degree in Computer Science, Information Systems, Engineering or related major
  • CISSP certification
  • CCNA/CCENT/CCNP certifications
  • GSEC or MCSA certification
  • CISM certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
125 Employees
Year Founded: 2012

What We Do

STEM Xpert is a consulting engineering firm recognized in the engineering industry for its commitment to client service and passion for excellence. The firm provides specialized professional consulting services in the fields of science, technology, engineering, and mathematics (STEM).

Similar Jobs

Benchling Logo Benchling

Artificial Intelligence Engineer

Cloud • Healthtech • Social Impact • Software • Biotech
Remote or Hybrid
US
605 Employees
176K-265K Annually

Coursera + Udemy  Logo Coursera + Udemy

Director, FP&A Systems and Transformation

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
178K-243K Annually

PNC Bank Logo PNC Bank

Technology Solution Center Analyst

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
37K-75K Annually

PNC Bank Logo PNC Bank

Software Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees

Similar Companies Hiring

Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account